Description
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Sureshbabu Narvaneni#
References
www.exploit-db.com/exploits/44492 (ExploitDB-44492)
www.joomsky.com (Official Product Homepage)
extensions.joomla.org/extension/js-jobs/ (Product Reference)
www.vulncheck.com/...nent-js-jobs-cross-site-request-forgery (VulnCheck Advisory: Joomla! Component Js Jobs 1.2.0 Cross-Site Request Forgery)